Malware · 10h ago
Socket found a Firefox add-on, pdf-para-texto@extensao.local, that was published on September 3 and turned malicious in version 1.4 on September 11, when it began fetching a remote payload to steal Google session cookies and automate account takeover.
The extension shipped without hardcoded malicious code, URLs, or exfiltration endpoints. After installation, it pulled its instructions from attacker infrastructure and injected code into real accounts.google.com pages, letting it capture the victim’s Google session cookie and any password reset value Google asked for.
That means store review of the package alone can miss the real payload if the harmful behavior is only downloaded later. For teams that allow or review browser extensions, the exposure sits in active Google sessions, not just in the add-on code that was published.
1 source covering this story
Malicious Firefox Extension Poses as PDF Identity Verifier to Hijack Google Accounts
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.
Part of the PlainSec briefing for 2026-09-24